Hi Friends
I have a problem in excel data export thru javascript. we create an excel object from javascript. at that time IE shows the warning message "An Activex ontrol on this page might be unsafe to interect with other part of the page. do you want to allow this interection?" shows. Our client dont want to enable the Unsafe manner chk box in security settings
So we tried to sign the excel object using sign tool and make the certificate to pfx and import in to IIS. after that also the same error message is comming. is there any solution ?
Thanks in advance
3 3833
Hi Friends
I have a problem in excel data export thru javascript. we create an excel object from javascript. at that time IE shows the warning message "An Activex ontrol on this page might be unsafe to interect with other part of the page. do you want to allow this interection?" shows. Our client dont want to enable the Unsafe manner chk box in security settings
So we tried to sign the excel object using sign tool and make the certificate to pfx and import in to IIS. after that also the same error message is comming. is there any solution ?
Thanks in advance
Remember SSL & security are for your benefit too. AOL's Instant Messaging Command Execution, HTML and JavaScript Injection Vulnerabilities
Here is a reference that may help: Designing Secure ActiveX Controls
Thanks for your reply.
I go thru the ref URL and i signed my excel.exe. but still the warning message is appear in my client side.
I used the following syntax
makecert -r -pe -n "CN=s6072" -b 01/01/2000 -e 01/01/2036 -eku 1.3.6.1.5.5.7.3 .1 -ss my -sr localMachine -sky exchange -sp "Microsoft RSA SChannel Cryptographic Provider" -sy 12 -sv key.pvk key.cer
cert2spc key.cer key.spc
signtool signwizard
and then used pvkimport.exe to convert pvk format and add in to IIS SSL Certificate.
Kindly guide me.
Thanks in advance
Soundar
As the continous of the the above problem we request microsoft to assist. They replied with some points.
This behavior is by design. Office applications such as Word, PowerPoint, Excel etc. cannot be automated with CreateObject (VBScript) or ActiveXObject (JScript) unless this security setting allows it. Therefore the problem is not specific to Excel or JScript. The reason that Excel object is not safe from a scripting environment is because Excel can potentially writes to the User’s local file system. For example, although Microsoft Excel is a trusted tool from a reputable source, a malicious script can use its automation model to delete files on the user's computer, install macro viruses, and worse.
To solve this problem, we recommend you choose one of the following options:
1) Add the web site to the trusted sites zone.
-OR-
2) Change the following security setting for the Intranet zone to either Prompt or Enable:
"Initialize and script ActiveX Controls Not Marked as Safe"
-OR-
3) Create your own custom ActiveX control using a language like VB6, MFC, or ATL and in this ActiveX control, write code that automates Excel. This ActiveX control will be signed with a digital certificate and will be marked safe for scripting.
The following article provides more details on this solution when automating Word from a web page:
286023 - HOWTO: Use a VB ActiveX Component For Word Automation From Internet
http://support.microso ft.com/default.aspx?sc id=KB;en-us;286023
Ref
Safe Initialization and Scripting for ActiveX Controls
http://msdn.microsoft. com/workshop/components/activex/safety.asp
Now the customer is agreed with the microsoft solution :-)
Thanks a lot
Soundar
Sign in to post your reply or Sign up for a free account.
Similar topics |
by: karen |
last post by:
hi, not sure if this is a php issue or an outlook issue or what.
trying to send an html message via php, and it looks fine in hotmail,
yahoo, and earthlink webmail, but when i receive the same message (via
earthlinkg) into outlook, there are two characters missing after every
equals = sign. of course, this destroys the html. (actually, i
haven't tried sending any plain text versions that include =. maybe
it messes up those too??) any...
|
by: Dave |
last post by:
I'm working on a program that will be parsing a protocol. My basic storage
element type is an array of characters or char*. The reason I am using
char* is because many of the socket and stream functions I'll be using take
char* as a parameter.
What I am seeing with my program is that when bit 7 is true, my integers are
being sign extended. Below is a program that should demonstrate my
problem. I am encountering this problem in a...
|
by: Lloyd Dupont |
last post by:
I'm writing a .NET 2.0 app
I want to deploy it in the net.
Apparently (due to an "unknow publisher warning" while downloading in the
browser) I have to give a strong name to my installer & my components.
My (.NET 2.0 beta2) project is a mix of C# & MC++.
- To authenticafe my MSI I need a .spc & a .pvk file
- To strongly named my C# assemblies with VS.NET 2005 I need to use a .pfx
file or a .snk file
- To strongly named my C++ assembly...
|
by: Jason Heyes |
last post by:
Does a function exist in the standard library to compute the sign of an
integer? Example:
int sign(int v)
{
return v > 0 ? 1 : (v < 0 ? -1 : 0);
}
Thanks.
|
by: Tony Hedge |
last post by:
Hello,
A .NET 1.1 web app...
I create a hyperlink with a complete filename, and the target is for a new
window to open. Right now the filenames are all PDF files.
Everything works fine, the PDF opens in a new window - until a filename
containing a # sign is clicked. A window still opens up but I get the
dreaded 'Page cannot be displayed' error. I wrapped the filename around the
encode method so that the # sign is properly encoded,...
| |
by: Mitchell Vincent |
last post by:
I've recently started signing all EXEs that come out of here. I would
like to verify the signature at startup to detect any changes to the EXE
itself. Is something like that possible?
I'm using VB.NET 2003..
--
- Mitchell Vincent
|
by: robert maas, see http://tinyurl.com/uh3t |
last post by:
I'm working on examples of programming in several languages, all
(except PHP) running under CGI so that I can show both the source
files and the actually running of the examples online. The first
set of examples, after decoding the HTML FORM contents, merely
verifies the text within a field to make sure it is a valid
representation of an integer, without any junk thrown in, i.e. it
must satisfy the regular expression: ^ *?+ *$
If the...
|
by: Kesavan |
last post by:
Is there any way to run a function or a code-block whenever the client-
server communication breaks off. (ie power-off, browser-crash...)
Why I need this is, I want to update a login-table to trace user's
leave the portal without proper log-off or sign-out.
Every time a user at proper sign-in, a flag is set & account is locked
until he sign-out by updating in the login-table.At sign-out the flag
is released & his account is ready to...
|
by: Phillip B Oldham |
last post by:
Are there any FOSS Python Single-Sign-on Servers?
We're looking to centralise the sign-on for our numerous "internal"
webapps (across multiple servers, languages, and domains) to speed
user management and application development.
I've searched around but can only seem to find OpenID servers, which
will probably be too "open" for our needs. Coding one up would
possibly take more time than we have, and we'd prefer something
maintained...
|
by: Hystou |
last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it.
First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
|
by: jinu1996 |
last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that captivates audiences and drives business growth.
The Art of Business Website Design
Your website is...
| |
by: Hystou |
last post by:
Overview:
Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For most users, this new feature is actually very convenient. If you want to control the update process,...
|
by: tracyyun |
last post by:
Dear forum friends,
With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
|
by: conductexam |
last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one.
At the time of converting from word file to html my equations which are in the word document file was convert into image.
Globals.ThisAddIn.Application.ActiveDocument.Select();...
|
by: TSSRALBI |
last post by:
Hello
I'm a network technician in training and I need your help.
I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs.
The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols.
I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
|
by: adsilva |
last post by:
A Windows Forms form does not have the event Unload, like VB6. What one acts like?
|
by: 6302768590 |
last post by:
Hai team
i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system
| |
by: muto222 |
last post by:
How can i add a mobile payment intergratation into php mysql website.
| |